CVE-2026-26185 | directus up to 11.14.0 reset_url timing discrepancy (GHSA-jr94-gj3h-c8rf)
A vulnerability, which was classified as problematic, was found in directus up to 11.14.0. Affected by this issue is some unknown functionality. Such manipulation of the argument reset_url leads to observable timing discrepancy.
This vulnerability is referenced as CVE-2026-26185. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.